about summary refs log tree commit diff
diff options
context:
space:
mode:
authorFranck Cuny <franck@fcuny.net>2022-04-05 19:39:32 -0700
committerFranck Cuny <franck@fcuny.net>2022-04-05 19:39:32 -0700
commitb54c018a59d94bee698d16e2f7f58990fb5d1cec (patch)
tree0b955217cd46ea327a812ac0dea4f6f44b470a05
parentrefactor default packages to a module (diff)
downloadworld-b54c018a59d94bee698d16e2f7f58990fb5d1cec.tar.gz
refactor users to a module
Diffstat (limited to '')
-rw-r--r--hosts/common/system/default.nix3
-rw-r--r--modules/system/default.nix2
-rw-r--r--modules/system/users/default.nix (renamed from hosts/common/system/users.nix)12
3 files changed, 11 insertions, 6 deletions
diff --git a/hosts/common/system/default.nix b/hosts/common/system/default.nix
index 2b48e4e..291314b 100644
--- a/hosts/common/system/default.nix
+++ b/hosts/common/system/default.nix
@@ -1,6 +1,5 @@
 { pkgs, ... }:
 
 {
-  imports =
-    [ ./boot.nix ./hardware.nix ./network.nix ./security.nix ./users.nix ];
+  imports = [ ./boot.nix ./hardware.nix ./network.nix ./security.nix ];
 }
diff --git a/modules/system/default.nix b/modules/system/default.nix
index 1f832bf..3f7d3ec 100644
--- a/modules/system/default.nix
+++ b/modules/system/default.nix
@@ -1 +1 @@
-{ ... }: { imports = [ ./console ./locale ./nix ]; }
+{ ... }: { imports = [ ./console ./locale ./nix ./users ]; }
diff --git a/hosts/common/system/users.nix b/modules/system/users/default.nix
index 7d847f3..b39067c 100644
--- a/hosts/common/system/users.nix
+++ b/modules/system/users/default.nix
@@ -1,6 +1,8 @@
 { config, lib, pkgs, ... }:
-
-{
+let
+  groupExists = grp: builtins.hasAttr grp config.users.groups;
+  groupsIfExist = builtins.filter groupExists;
+in {
   # Users are managed through this configuration. If a user is added
   # manually, it will be removed on system activation.
   users.mutableUsers = false;
@@ -12,7 +14,11 @@
     group = "fcuny";
     home = "/home/fcuny";
     shell = pkgs.fish;
-    extraGroups = [ "users" "wheel" "docker" ];
+    extraGroups = groupsIfExist [
+      "docker"
+      "users"
+      "wheel" # `sudo` for the user.
+    ];
     hashedPassword =
       "$6$i.z1brxtb44JAEco$fDD2Izl.zRR9vBCB2VBKPScChGw38EEl7QEiBTJ/EwgP3oSL0X3ZHq0PJ.RtqzBsWTPUjl4F3MKOBMhnaAPr6.";
     openssh.authorizedKeys.keys = [